IBM Cognos Analytics PowerPlay (IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7) could be vulnerable to an XML Bomb attack by a malicious authenticated user. IBM X-Force ID: 196813.
The product uses XML documents and allows their structure to be defined with a Document Type Definition (DTD), but it does not properly control the number of recursive definitions of entities.
| Name | Vendor | Start Version | End Version | 
|---|---|---|---|
| Cognos_analytics | Ibm | 11.1.7 (including) | 11.1.7 (including) | 
| Cognos_analytics | Ibm | 11.2.0 (including) | 11.2.0 (including) | 
| Cognos_analytics | Ibm | 11.2.1 (including) | 11.2.1 (including) |